Run vendor risk assessments and internal system assessments via a single, easy to run library
Reduce assessment fatigue among your vendors and internal teams
Save time on managing assessments
See where every assessment stands in one view, instead of chasing people on email and WhatsApp threads
What you can assess via Consentin Unified Assessments
Vendors and data processors
The third parties you share personal data with.
Internal systems
The applications, databases and tools your own teams run.
Processing activities and purposes
Assess a specific activity or purpose on its own.
Configure and manage assessment questions via a question library
Flexible fields: Boolean, dropdown, multi-select, text, number and file upload, held in one library and reused across assessments
Conditional logic: A responder only sees and answers the questions relevant to them
Ready templates: DPIA, TPRA, ISO 27001 and ISO 27701, or build your own. Edit a question inside one template without changing it anywhere else
Library export: Export your risk definitions, questions and templates as a single file and import them into another environment or tenant
Run a preliminary assessment to reduce turnaround times
Send third parties a short screening assessment to determine whether they need a full assessment
Record a yes/no decision on whether a full assessment is required, with a mandatory written justification, stored in Result History
Send a full assessment to relevant external vendors and internal owners
Vendors, third parties and internal owners receive assessments via email link
Assign individual questions to relevant POCs, technical questions to the vendor's engineer, contractual ones to their legal contact etc. Each responder sees only their own questions rather than a full assessment
Responders can attach proof against each question on the portal
Review and control every response from one place
Assessment tracker
Every open assessment in one view, with how long each has been sitting with you or with the vendor.
Dynamic, live assessments
Mark statuses and responses in real time, without waiting for the assessee to finish the entire questionnaire.
Every question comes with a chat thread
So clarifications happen inside the assessment instead of separate email threads.
Detailed logs
The record of what you reviewed and what you concluded, timestamped against each question.
Feed assessment findings into an automatic risk register
Auto risk detection based on the responses with no manual tagging
Every risk links back to the assessment, question and response that produced it
Run the same assessment again in the next cycle without rebuilding it
Run the same template on the same entity with the same responders. The previous cycle stays intact with its responses, evidence and decisions
Fold the cycle into the infosec or sectoral audit you already run rather than adding a separate one
See your own questionnaire running in Consentin
Bring your current assessment questionnaire to a 30-minute walkthrough. We'll build it in the platform, send it to a test responder, and show you the risks landing in the register.
Frequently asked questions
Do vendors need a Consentin account or a login?
No. Vendors get an email link, answer the questions assigned to them, attach evidence and submit. There is nothing to install and no licence to buy for them.
Does Consentin scan our systems, or our vendors' systems?
No. An assessment asks questions and collects evidence against them — nothing is scanned and nothing is installed at either end. Discovering personal data across your own structured and unstructured sources is Lens, a separate product that inventories data rather than vendors.
Does Consentin verify what a vendor tells us?
No. Vendors self-report and attach their own evidence. Every answer carries a tracked review history, so you can challenge a response, send a single question back for more detail, and show what you checked.
Can I send one assessment to several vendors at once?
Yes, by adding each vendor to the scope of one assessment and assigning that vendor's questions to their contact. If the vendors need genuinely different question sets, create an assessment per vendor — one assessment carries one questionnaire.
Can different partner types get different questionnaires?
Yes. Build a template per partner type — a full set for a partner processing personal data, a short set for one supplying headcount only — and load the right template into each assessment.
How does an assessment know which questions to ask?
Three ways, and they combine. Questions tagged to an entity appear when that entity is in scope, a template loads a saved set, and you can add individual questions from the library.
Can I run the same assessment again next cycle?
Yes. Run the same template on the same entity with the same responders, and the earlier cycle stays intact as its own record.